Automation has transformed compliance. The real questions now are how much to automate and where human intelligence stays non-negotiable. Chris Newton-Smith at IO explains how to get an honest read on your security posture

Information security is an area where mistakes are costly. When controls fail, the financial, operational and reputational fallout can be significant and slow to reverse, which is why organisations tend to hold themselves to a high standard here.
In adhering to best practices, nailing compliance is non-negotiable. And, notably, 51% of organisations see cyber-security and data privacy/protection as a top compliance priority, according to PwC’s Global Compliance Survey 2025.
However, turning priority into reality has become increasingly difficult. As regulatory requirements have continued to evolve, organisations now find themselves faced with navigating a growing web of cyber-security, privacy and data protection obligations.
Already stretched compliance teams are now under increasing pressure, required to continuously monitor regulatory changes, gather evidence, manage audits and demonstrate alignment with various requirements across multiple frameworks. And, as a result, many organisations are finding that traditional, manual approaches to compliance have become unsustainable.
PwC’s report shows that 77% of organisations feel compliance complexity is negatively impacting their company. 90% say that regulatory complexity has hindered the implementation of new IT systems, for example, while it has also limited AI usage among two-thirds of companies surveyed.
Green compliance dashboards: an Achilles heel
It is for this reason that the compliance automation market has taken off, providing firms with the means of reducing the human effort required to achieve and maintain compliance certification.
Industry forecasts suggest that the global compliance automation tools market could grow by up to 20% per year on average between 2025 and 2030. And we have already seen the hype translate into adoption. Many companies are automating the production of evidence to achieve certification to standards such as ISO 27001 and ISO 27701, for example. Yet question marks remain around the extent to which organisations understand how that evidence is created, interpreted and validated by the automated systems they’re using.
The challenge here is that compliance is sometimes wrongly viewed as an administrative burden or tick-box exercise, when in reality, security and compliance are much more nuanced.
Organisations must be clear about the risks of a checklist-style approach. For example, a firm may install a critical patch on most systems to ensure they’re compliant, only to then fail to implement the same key updates on their most sensitive servers. Similarly, a company may enable MFA for all employees to ensure they’re compliant, but might not ensure the same rules apply for contractors.
Essentially, if compliance is treated as a tick-box exercise, then real risks can be overlooked. A company might appear “green” in their compliance dashboard, all while having failed to address fundamental security issues.
Acknowledging what automation can’t do
Here lies the limitations of automation on its own. While technologies are great at confirming whether or not a control exists, they are much less able to judge if that control is adequately addressing the full scale of potential problems or risks.
There is no doubt that automation can dramatically improve the efficiency of compliance efforts and visibility across compliance programmes. But problems can arise when organisations treat these systems as a single source of truth that provides unquestionable evidence of security effectiveness.
When automated dashboards, reports and evidence collection tools give the impression that everything is as it should be, a trust gap can open up, giving organisations confidence that security controls are working as intended, when in reality weaknesses or exceptions may lie hidden beneath the surface.
Organisations need to ensure that automated tools don’t blur the lines between compliance and security. The former demonstrates that controls exist but aren’t necessarily an indicator that those controls are being used to the greatest effect.
Gaps in market understanding remain
Fortunately, many organisations already see this trust gap emerging.
According to a recent IO survey of over 250 UK cyber-security managers, the highest proportion of respondents (44.6%) say human expertise is needed to assess whether automated compliance processes are accurate, relevant and contextually meaningful. The same survey found that nearly one third feel there is a growing need for practitioners to challenge the credibility and integrity of automated compliance evidence before it is trusted by auditors, regulators or customers.
It’s a clear recognition of the fact that automated evidence should never be accepted at face value simply because it has been generated automatically. To have defensible trust in the automated evidence collection, there needs to be rigorous human oversight from experienced practitioners who can accurately identify compliance gaps. However, clearly, much of the market is still yet to catch up with this reality.
IO’s research also highlights another real concern: that the speed of compliance, accelerating under automated compliance tools, is beginning to outpace assurance. 87% of respondents stated that they felt the speed at which compliance is achieved affects its credibility, potentially leading to serious security blind spots.
Balancing automation with human oversight
To address these issues and fundamentally close the trust gap that set-and-forget automation are at risk of creating, firms need to view automation as a tool to enhance compliance efficiency and effectiveness, rather than a single source of truth.
A genuine understanding of an organisation’s security posture requires leaders to get curious and peel back the layers on security and compliance controls. Are they operating as intended? Do exceptions exist that automated compliance tools have failed to identify? And do those exceptions present real security issues?
Automated evidence must be challenged in this way to ensure it is continuously checked and validated. That doesn’t mean firms have to go back to manual reviews and audits. Instead, they should combine technologies with human oversight and expertise to go beyond compliance and achieve genuine resilience.
The goal should never be check-box compliance, or compliance for compliance’s sake. That’s where issues and automated trust gaps emerge. Rather, companies should always focus on ensuring they have a clear, accurate understanding of the organisation’s true security posture.
In an environment where trust matters more than ever, speed alone proves nothing. What earns trust is knowing your controls genuinely work and being able to evidence it. Automation gets organisations part of the way; experienced human oversight closes the gap. That combination is what turns compliance from a point-in-time exercise into genuine resilience.
Chris Newton-Smith is CEO at IO
Main image courtesy of iStockPhoto.com and narvo vexar


© 2025, Lyonsdown Limited. Business Reporter® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543